5.3

CVSS4.0

CVE-2025-14052 - youlaitech youlai-mall members getMemberById access control

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper access controls. The attack is possible to be carried out remotel…

πŸ“… Published: Dec. 5, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 10, 2025, 11:29 p.m.

4.3

CVSS3.1

CVE-2025-32900 -

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 o…

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-32898 -

The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2016-20023 -

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 4:09 p.m.

2.7

CVSS3.1

CVE-2025-14082 - Keycloak-services: keycloak admin rest api: improper access control leads to sensitive role metadat…

A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 3:30 p.m.

4.3

CVSS3.1

CVE-2025-32901 - kde-connect: KDE Connect: Application crash via malicious device IDs

In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-65897 -

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files …

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:52 p.m.

7.2

CVSS3.1

CVE-2025-66644 -

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.5

CVSS3.1

CVE-2025-64053 -

A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:17 a.m.

7.5

CVSS3.1

CVE-2025-65878 -

The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to th…

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:51 p.m.
Total resulsts: 349182
Page 2814 of 34,919
Β« previous page Β» next page
Filters